fix: restore action SHA-pinning and drop unneeded fetch-depth in CI/release workflows - #441
Conversation
…ormance release.yml (added in openedx#425, touched again in openedx#434/openedx#435/openedx#436/openedx#438) had drifted from the org's gold-standard reference (sample-plugin's release.yml): python-semantic-release, actions/upload-artifact and actions/download-artifact were on floating version tags (@v10.6.2, @v7, @v8) instead of pinned commit SHAs, defeating the whole point of the pin-actions-to-sha effort (this repo's own openedx#407) for the one workflow that runs unreviewed on every push to master. Also: - Drop `fetch-depth: 0` from the release job's checkout: python-semantic- release auto-deepens a shallow clone itself before evaluating version history, so it's never needed here (confirmed against sample-plugin). - Add `if-no-files-found: error` to the dist upload step so a build that silently produces no artifacts fails loudly instead of shipping an empty release. - Add the `github.ref_name == 'master'` guard to publish_to_pypi's `if:`, matching sample-plugin, even though this workflow currently only triggers on push to master. All three added SHAs were independently verified against the upstream repos via `gh api repos/<owner>/<repo>/commits/<sha>` and cross-checked against their claimed tags (resolving through the annotated tag object for python-semantic-release@v10.6.2, which points at commit 9a026e9303981c866c3425723009becb2437c757). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Nothing in this package reads __version__ at runtime (setuptools_scm's dynamic version, with fallback_version = "0.0.0", is only ever consumed via package metadata, never parsed from a module attribute), so there's no analog to the openedx-events EventData.sourcelib case where a shallow clone breaks version resolution. Sample-plugin's own backend-ci.yml doesn't set fetch-depth: 0 either. A full clone on every CI run buys nothing here and just makes checkout slower. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Thanks for the pull request, @irfanuddinahmad! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
Summary
Follow-up audit of #425 (Python tooling modernization) against this org's
current gold-standard Phase 3 reference (openedx/sample-plugin's
release.yml). Found thatrelease.ymlhad drifted from full SHA-pinningover the course of #425/#434/#435/#436/#438 and picked up two other small
conformance gaps:
python-semantic-release/python-semantic-release,actions/upload-artifact,and
actions/download-artifactwere on floating tags (@v10.6.2,@v7,@v8) instead of pinned commit SHAs. This defeats the point of this repo'sown prior pin-actions-to-sha effort (chore: pin GitHub Actions workflows to full commit SHAs #407) for the one workflow that runs
unreviewed on every push to
master. Pinned to:python-semantic-release/python-semantic-release@9a026e9303981c866c3425723009becb2437c757 # v10.6.2actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1All three verified via
gh api repos/<owner>/<repo>/commits/<sha>, cross-checked against their claimed tags.
fetch-depth: 0from the release job's checkout: python-semantic-release deepens a shallow clone itself before evaluating version history,
so it's never needed there.
if-no-files-found: errorto the dist upload step, and thegithub.ref_name == 'master'guard topublish_to_pypi'sif:, bothmatching sample-plugin exactly.
fetch-depth: 0fromci.yml's checkout too: nothing in thispackage reads
__version__at runtime (no analog to the openedx-eventsEventData.sourcelibcase), and sample-plugin's ownbackend-ci.ymldoesn't set it either.
Test plan
masterexercises the release job with the newly-pinnedSHAs